title: Detect Activity to Known Malicious Cryptomining - URLhaus urls - Chunk 1
id: 3316af2f-5b86-5439-89c7-8ee743b4dbdf
status: experimental
description: Detects traffic or activity related to known malicious urls associated with Cryptomining from URLhaus (Chunk 1).
logsource:
  category: proxy
detection:
  selection:
    c-uri:
      - '*http://106.54.223.106/phpmyadmin/setup/lib/syscon*'
      - '*https://msfconfig.icu/tmp/system.txt*'
      - '*http://158.94.208.44/pb7Ulzhaae3xpSNrEvJH5yqqyMyIbnNF/mKM65Cf6QNqeOVw9.exe*'
      - '*https://davestrap.xyz/installer.exe*'
      - '*https://lightcord.xyz/downloads/LightCord-Setup-Win.exe*'
      - '*http://165.22.14.76/sex.sh*'
      - '*https://217.60.195.113/test/clean*'
      - '*https://217.60.195.113/test/arm7*'
      - '*https://217.60.195.113/test/riscv*'
      - '*https://217.60.195.113/test/i686*'
      - '*https://217.60.195.113/test/aarch64*'
      - '*https://217.60.195.113/test/x86_64*'
      - '*http://endpoint.project0.cc/f/m/.X0-lock_x86_64*'
      - '*https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/config.json*'
      - '*https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/w2.sh*'
      - '*https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/check2.sh*'
      - '*http://205.185.127.10/xg*'
      - '*http://dutalogambone.com/144.exe*'
      - '*http://dutalogambone.com/3.exe*'
      - '*http://46.151.182.131/all.sh*'
      - '*http://91.92.242.236/files-129312398/files/file_3023e225bbb525a2.exe*'
      - '*http://91.92.242.236/files-129312398/files/file_b82f2dba4422534f.exe*'
      - '*http://91.92.242.236/files-129312398/files/file_9ed873a1d14ec6de.exe*'
  condition: selection
level: high
tags:
  - attack.t1496
  - source.URLhaus
---
title: Detect Activity to Known Malicious Cryptomining - URLhaus urls - Chunk 1
id: 5d9e1d92-b2c4-5b25-8e48-0c8b2432093e
status: experimental
description: Detects traffic or activity related to known malicious urls associated with Cryptomining from URLhaus (Chunk 1).
logsource:
  category: proxy
detection:
  selection:
    c-uri:
      - '*http://47.239.127.71/lib/xxx*'
  condition: selection
level: high
tags:
  - attack.t1583
  - source.URLhaus
---
title: Detect Activity to Known Malicious Cryptomining - URLhaus urls - Chunk 1
id: f42dab2b-f6e3-5181-ac2d-d61e4dcc95d4
status: experimental
description: Detects traffic or activity related to known malicious urls associated with Cryptomining from URLhaus (Chunk 1).
logsource:
  category: proxy
detection:
  selection:
    c-uri:
      - '*http://endpoint.project0.cc/f/init.cfg*'
  condition: selection
level: high
tags:
  - attack.t1059.004
  - source.URLhaus
---
title: Detect Activity to Known Malicious Cryptomining - MalwareBazaar hashs - Chunk 1
id: a9489914-32b3-565d-900f-897d9a586db4
status: experimental
description: Detects traffic or activity related to known malicious hashs associated with Cryptomining from MalwareBazaar (Chunk 1).
logsource:
  category: process_creation
detection:
  selection:
    hashes:
      - ' "ca116b3d7caea85d448cc674087381d06902d80f2d2842e8dc22cd4b266379b5"'
      - ' "20dcf6d45f17d62279183276675ea33876e6846d3fdc09285e78e9819882b97e"'
      - ' "9885939da17f13c0dbb0973bb0f8393f6170a8273da18bc7c31d9f88645985ce"'
      - ' "0ba4e432149c97026ed7a0eed01d46e86514dd2ad06525a98f9bd16f700177fc"'
      - ' "803b8565ecdec7a649d08f9ca48cb2a75307a87b36e92f993f5f5e615384ea94"'
      - ' "e52e8e2ebfc9964e216fbee0d6a48423b59e6b4212b7a6d3a2ec7d5e72e300d9"'
      - ' "a6fbff58f3f4137fffa2f0d046343f7245c4a69ebd79df25aa2d2c0197af1a94"'
      - ' "84b41806926f1046b6e23b7b8b1f1665c095b5e68d8b73ce71516a4beebf254a"'
      - ' "40560c7370ec0e7d3f9eedf55774cd9fc09f13f1a01f822e9d8830b57ea8d9cc"'
      - ' "30cf8b82a53fff20b564597e56123ddeb16a87441a8b94f621e52c3213aeaa2c"'
  condition: selection
level: high
tags:
  - attack.t1071
  - source.MalwareBazaar
